Skip to content

New Query: Ransomware Precursors#68

Merged
dweissbacher merged 1 commit into
mainfrom
submission/8c03f9ce-07ba-43f5-882a-22effd6cfa22
Jul 2, 2026
Merged

New Query: Ransomware Precursors#68
dweissbacher merged 1 commit into
mainfrom
submission/8c03f9ce-07ba-43f5-882a-22effd6cfa22

Conversation

@byteray-cql-hub-bot

Copy link
Copy Markdown
Contributor

New Query Submission

Name: Ransomware Precursors
Author: ByteRay GmbH
Submission ID: 8c03f9ce-07ba-43f5-882a-22effd6cfa22

Description

Detects command patterns that ransomware operators execute immediately before encryption to prevent recovery: Volume Shadow Copy deletion (vssadmin, WMIC, PowerShell WMI/CIM), backup catalog destruction (wbadmin), Windows Recovery Environment tampering (bcdedit), USN journal deletion (fsutil), and mass shadow storage resizing. Each event is classified into a named hypothesis so analysts can triage by technique. These commands are rare in legitimate day-to-day operation and their appearance - especially several within a short window on the same host - is one of the strongest early-warning signals of an imminent ransomware detonation.


This PR was automatically created by the CQL Hub submission pipeline.

@dweissbacher
dweissbacher merged commit cefe2a5 into main Jul 2, 2026
2 checks passed
@dweissbacher
dweissbacher deleted the submission/8c03f9ce-07ba-43f5-882a-22effd6cfa22 branch July 2, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant